Resources · 118
TLS renewal: verify the certificate actually being served
Follow renewal through every termination point and supported client before declaring the change complete.
· 2 min
What this guide helps achieve
- Inventory TLS termination points
- Prepare issuance, distribution and reload
- Verify through clients and monitor
Quick check
- Termination map and observed expiries.
- Verified renewal and distribution procedure.
- Client evidence, alerts and change completion criteria.
Step-by-step method
- 01
Inventory TLS termination points
List expected names, CDNs, load balancers, proxies and internal connections presenting certificates. Record actual served certificate, chain, expiry and owner at each relevant point. Successful issuance does not establish installation on every node. Protect private keys and exclude them from the register.
Termination map and observed expiries.
- 02
Prepare issuance, distribution and reload
Test automation against provider staging where available. Check validation challenges, SAN name coverage, protected storage and component reload. Avoid issuance on every instance startup when a usable certificate exists under your key policy.
Verified renewal and distribution procedure.
- 03
Verify through clients and monitor
Check names, validity dates and trust chain with supported clients over relevant paths. Keep TLS verification enabled. Monitor the served certificate’s expiry, not just scheduler status. Rollback requires a still-valid certificate and uncompromised key; otherwise fix or isolate the failing point.
Client evidence, alerts and change completion criteria.
Acceptance case to reproduce
Fictional example: these inputs describe no customer or observed result.
View case inputs
{
"issuance_succeeded": true,
"proxy_count": 2,
"proxies_serving_expected_certificate": 1,
"other_proxy_certificate_expired": true,
"tls_verification_enabled": true,
"expected": "change_incomplete_fix_and_verify_client_paths"
}Expected decision
Fictional example: renewal succeeds, but one of two proxies still serves an expired certificate. The change remains incomplete: fix that proxy and check client paths instead of disabling TLS validation.
Your acceptance workbook
Record observations against this guide’s criteria. A record is not certification.
The workbook does not save automatically. Export before leaving.
Filters do not limit exports. Actions include issues and unreviewed criteria.
Import replaces current observations after your confirmation.
Management indicators
| Indicator | What it measures | First action |
|---|---|---|
| Verified current terminations | Checked points serving expected certificates / inventoried points | Disclose unobservable points |
| Minimum observed time to expiry | Shortest remaining validity among checked served certificates | State observation time and coverage |
Common pitfalls
Frequently asked questions
Is successful ACME renewal enough to close the change?
No. Verify distribution, reload and the certificate actually presented to clients. One node may still serve an older certificate.
Official references
References consulted: . The method and worksheet propose checks to adapt to your context; they do not constitute certification.






